Method for controlling safe startup and registration of electronic device and related control circuit
Through the combination of a safe boot control circuit and a signature device, the reference code is generated and the activation code is compared with the activation code by using the entropy source and digital circuit, the reverse engineering and overproduction problems of integrated circuit design are solved, and the safe activation and anti-imitation of electronic devices are realized.
Patent Information
- Application Number
- CN202111489641.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-12-11
- Filing Date
- 2021-12-08
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2041-12-08
AI Technical Summary
The prior art cannot effectively prevent integrated circuit designs from being reverse engineered, copied and over-production, resulting in unauthorized persons using or manufacturing excessive integrated circuits.
The safe boot control circuit is adopted to provide a random number sequence through the entropy source, generate a reference code and compare it with the stored activation code, and determine that the function of the electronic device is enabled; a signature device is used to send a one-time random number and public key generation response, and determine that the activation code is written; combined with anti-tampering circuit and digital circuit, the entropy source output is ensured as a fingerprint to prevent reverse engineering and imitation.
Ensure that only authorized electronic devices have the correct activation code, avoid malicious imitation and over-production chips being activated or used, and improve the security of integrated circuits.
Smart Images

Figure CN114626021B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to anti-reverse-engineering, anti-counterfeiting / anti-cloning, and anti-overproduction, and more particularly to a method for controlling secure startup of an electronic device, a secure startup control circuit, and a method for controlling registration of the electronic device. Background Art
[0002] After an IC design company completes the design of an integrated circuit, it is manufactured by a third party, such as a foundry. Although the IC design company requires the foundry to manufacture only a certain number of ICs based on the design, these ICs are typically overproduced. In some cases, these overproduced ICs may be obtained by someone unauthorized by the IC design company. Therefore, secure boot controls are necessary to prevent unauthorized use of these overproduced ICs.
[0003] Additionally, existing analysis tools can reverse engineer the Graphic Data System (GDS) files of integrated circuit designs to obtain the internal architecture of the integrated circuit. Therefore, a novel method and related electronic device are needed to prevent chips from being maliciously reverse engineered or copied through GDS analysis and reverse engineering techniques. Summary of the Invention
[0004] Therefore, an object of the present invention is to provide a method for controlling a safe startup of an electronic device, a safe startup control circuit, and a method for controlling a registration of an electronic device to solve the problems of the related art.
[0005] At least one embodiment of the present invention provides a method for controlling a secure boot of an electronic device. The method is applicable to a secure boot control circuit of the electronic device and includes: checking the randomness of an output of an entropy source of the secure boot control circuit to generate a check result; utilizing the entropy source to provide a random number sequence; generating a reference code based on the random number sequence; comparing the reference code with an activation code stored in the secure boot control circuit to generate a comparison result; and determining whether to enable at least one function of the electronic device based on at least one of the check result and the comparison result.
[0006] At least one embodiment of the present invention provides a method for controlling the registration of an electronic device. The method includes: using a signature device to send a one-time random number (nonce) to a secure boot control circuit of the electronic device; using the secure boot control circuit to generate a response based on a first public key (shared key) of the electronic device and the one-time random number; using the signature device to generate an encoding result based on a first public key of the signature device and the one-time random number; and using the signature device to determine whether to write an activation code into the electronic device, wherein the activation code is generated based on the first public key and a bit sequence.
[0007] At least one embodiment of the present invention provides a secure boot control circuit for controlling the secure boot of an electronic device, wherein the electronic device includes the secure boot control circuit. The secure boot control circuit includes: an anti-tampering circuit, a first digital circuit, and a second digital circuit. The anti-tampering circuit includes an entropy source, and the entropy source is used to provide a random number sequence. The first digital circuit is coupled to the anti-tampering circuit and is used to control the reading of the random number sequence. The second digital circuit is coupled to the first digital circuit and is used to control the operation of the secure boot of the electronic device. In particular, the secure boot control circuit checks the randomness of an output of the entropy source of the secure boot control circuit to generate a check result; the secure boot control circuit generates a reference code based on the random number sequence; the second digital circuit compares the reference code with an activation code stored in the secure boot control circuit to generate a comparison result; and the second digital circuit determines whether to enable at least one function of the electronic device based on at least one of the check result and the comparison result.
[0008] The method and secure boot control circuit provided by embodiments of the present invention can use the entropy source output as a fingerprint of an electronic device after the entropy source is initialized. Furthermore, an activation code corresponding to this fingerprint must be written into the secure boot control circuit to activate the electronic device incorporating the secure boot control circuit. Because this fingerprint cannot or is difficult to reverse engineer or replicate using conventional analysis tools, it ensures that only authorized electronic devices possess the correct activation code, thereby preventing maliciously counterfeit or overproduced chips from being activated or used. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Figure 1 FIG. 1 is a schematic diagram of a manufacturing process of an electronic device according to an embodiment of the present invention.
[0010] Figure 2According to an embodiment of the present invention, a method for controlling Figure 1 The workflow of the method for safely starting up an electronic device is shown.
[0011] Figure 3 According to an embodiment of the present invention Figure 2 The workflow of the control scheme of the method is shown.
[0012] Figure 4 According to an embodiment of the present invention, a method for controlling Figure 1 FIG. 1 is a schematic diagram of a safe power-on control circuit for safely powering on an electronic device.
[0013] Figure 5 According to an embodiment of the present invention, a method for controlling Figure 1 The workflow of the method for registering an electronic device is shown.
[0014] Figure 6 According to an embodiment of the present invention, Figure 5 After registration shown Figure 1 The workflow of the safe power-on control solution for an electronic device is shown.
[0015] Figure 7 A signature device according to an embodiment of the present invention is used to sign an electronic device. Figure 5 Schematic diagram of a part of the workflow.
[0016] Figure 8 A signature tool according to an embodiment of the present invention is used to sign an electronic device. Figure 5 A schematic diagram of another part of the workflow.
[0017] Figure 9 A signature tool according to another embodiment of the present invention is used to sign an electronic device. Figure 5 A schematic diagram of another part of the workflow.
[0018] Figure 10 A control scheme for authenticating an activation code of an electronic device according to an embodiment of the present invention is provided.
[0019] Figure 11 A control scheme for authenticating an activation code of an electronic device according to another embodiment of the present invention is provided.
[0020] The description of the accompanying drawings is as follows:
[0021] 10 System on a Chip
[0022] 100 Safety start control circuit
[0023] 100C Activation Code
[0024] 100FP unique pattern
[0025] Steps S210-S250, S310-S390
[0026] 40 Safety start control circuit
[0027] 400 Anti-tamper circuit
[0028] 410 Entropy Source
[0029] 420 Hardened Register Transfer Stage Circuit
[0030] 430 Safety Function Digital Circuit
[0031] 440 Private Bus
[0032] 450 standard interface
[0033] Steps S510-S580, S610-S694
[0034] 70 Single-Chip System
[0035] 70R response
[0036] 700 Signature Tool
[0037] 700N One-time random number
[0038] 71, 72, 710, 720 Secure Hash Algorithms
[0039] 73, 730 Hash-based message authentication algorithm
[0040] 76 Encryption-based Message Authentication Code Algorithm
[0041] 73C, 76C reference code
[0042] 730C encoding results
[0043] 74 One-time programmable memory
[0044] 74C Activation Code
[0045] 75, 750 comparators
[0046] 760 Count Control
[0047] PWD1, PWD2 public keys
[0048] PWD UID Unique identifier
[0049] PWD BS bit sequence
[0050] V CMP Comparison results DETAILED DESCRIPTION
[0051] Figure 1 The present invention is a schematic diagram illustrating a manufacturing process for an electronic device, such as a system on a chip (SoC) 10, according to an embodiment of the present invention. SoC 10 includes a secure boot control circuit 100. In this embodiment, secure boot control circuit 100 includes an entropy source. The entropy source can be implemented using a static entropy source, such as a physical unclonable function (PUF) device, or a dynamic entropy source, such as a true random number generator (TRNG), but the present invention is not limited thereto. SoC 10 also includes a central processing unit (CPU) (in the figure for simplicity), a random access memory (RAM) (in the figure for simplicity), and at least one functional circuit (in the figure for simplicity), but the present invention is not limited thereto.
[0052] When the SoC 10 is manufactured in the chip probing (CP) stage or the final test (FT) stage, the manufacturer may initialize the entropy of the SoC 10 (especially the entropy source of the secure boot control circuit 100 therein) (in the Figure 1The secure boot control circuit 100 (e.g., the entropy source therein) generates a unique pattern 100FP for the SoC 10. This unique pattern 100FP serves as the fingerprint of the SoC 10. Because the unique pattern 100FP is generated by hardware within the SoC 10 after the entropy initialization, hackers cannot or will find it difficult to reverse engineer the unique pattern 100FP. Consequently, a maliciously counterfeited chip (e.g., one that skipped the entropy initialization step) does not possess a valid fingerprint. The boot process of this counterfeit chip will be interrupted due to the lack of a valid fingerprint, thus achieving anti-counterfeiting / anti-cloning protection. Furthermore, the secure boot control circuit 100 includes at least one analog functional circuit and certain digital circuits implemented using a customized cell library. Therefore, the secure boot control circuit 100 cannot or will find it difficult to reverse engineer using conventional reverse engineering techniques, thus achieving anti-reverse engineering protection.
[0053] When the manufacturing process of the system-on-chip 10 enters the chip activation stage on a module such as a printed circuit board (PCB) (in Figure 1 In the chip, a signature tool can be coupled to the single chip system 10 to activate an activation code 100C (in Figure 1 The activation code 100C stored in the system-on-chip 10 is written into the one-time programmable (OTP) memory of the system-on-chip 10 (denoted as "AC" for simplicity). The correctness of the activation code 100C stored in the system-on-chip 10 is checked during the secure boot process of the system-on-chip 10. In some embodiments, the signature tool is used to activate only a specific number of chips. The boot process of chips produced in excess will be interrupted due to the lack of the correct activation code, thereby preventing overproduction.
[0054] Figure 2 According to an embodiment of the present invention, a method for controlling an electronic device (eg Figure 1 The workflow of the method for secure booting of the single chip system 10 is shown, wherein the method is applicable to a secure booting control circuit (eg, Figure 1 It should be noted that one or more steps may be performed in Figure 2 The steps shown in the figure may be added, deleted, or modified. In addition, the steps do not have to be exactly the same if the same results are achieved. Figure 2 Execute in the order shown.
[0055] In step S210 , the secure boot control circuit 100 may check the randomness of an output of an entropy source (eg, a physically unclonable function source or a true random number generator) of the secure boot control circuit 100 to generate a check result.
[0056] In step S220 , the secure boot control circuit 100 may utilize the entropy source to provide a random number sequence according to the check result.
[0057] In step S230 , the secure boot control circuit 100 may generate a reference code according to the random number sequence.
[0058] In step S240, the secure boot control circuit 100 compares the reference code with an activation code (eg, a one-time programmable memory) stored in the secure boot control circuit (eg, Figure 1 The activation code 100C) shown is compared to generate a comparison result.
[0059] In step S250, the secure boot control circuit 100 may determine whether to enable at least one function of the electronic device (e.g., the single chip system 10) based on at least one of the check result and the comparison result. In some embodiments, when the check result indicates that the output of the entropy source (e.g., the fingerprint such as Figure 1 If the randomness of the unique pattern 100FP) shown cannot meet the predetermined standard, the workflow may end at step S210 and steps S220 to S240 may be skipped, but the present invention is not limited thereto.
[0060] Figure 3 According to an embodiment of the present invention Figure 2 Note that one or more steps may be Figure 3 The steps shown in the figure may be added, deleted, or modified. In addition, the steps do not have to be exactly the same if the same results are achieved. Figure 3 In this embodiment, it is assumed that the entropy initialization of the single-chip system 10 (eg, the secure boot control circuit 100 ) has been completed, that is, the fingerprint of the single-chip system 10 , such as the unique pattern 100FP, has been generated.
[0061] In step S310, the system-on-chip 10 is powered on (at Figure 3 (labeled "chip on" for simplicity).
[0062] In step S320, the single chip system 10 activates its fingerprint (in Figure 3(labeled as “enabling fingerprint” for simplicity). For example, the single-chip system 10 turns on the power to the secure boot control circuit 100 to make the unique pattern 100FP readable.
[0063] In step S330, the SoC 10 performs a ready check of the fingerprint of the SoC 10 to check whether the fingerprint of the SoC 10 is ready, and generates a ready check result accordingly. In some embodiments, the secure boot control circuit 100 includes a counter (not shown for simplicity). Figure 1 ) to generate a count result, wherein the count result is used to indicate a period of time starting from the time when the single chip system 10 is powered on. A ready flag of the fingerprint of the secure boot control circuit 100 may be set in response to the count result indicating that the period of time has reached a predetermined time threshold. For example, the single chip system 10 may check whether the flag of the entropy source of the secure boot control circuit 100 is set (in Figure 3 If the readiness check result is "yes", the process proceeds to step S360; and if the readiness check result is "no", the process proceeds to step S350.
[0064] In step S350, the safe boot of the SoC 10 fails ( Figure 3 (labeled as "boot failure warning" for simplicity). In some embodiments, when the secure boot of the system-on-chip 10 fails, all functions of the system-on-chip 10 are disabled and the system-on-chip 10 will be shut down. In some embodiments, when the secure boot of the system-on-chip 10 fails, the overall boot of the system-on-chip 10 will continue, but at least one function of the system-on-chip 10 will be disabled (e.g., remain inactive). For example, the secure boot control circuit 100 may send a boot failure warning signal to the central processing unit of the system-on-chip 10, and the central processing unit may disable all functional blocks, modules and / or circuits of the system-on-chip 10 in response to the boot failure warning signal. For another example, when the central processing unit of the system-on-chip 10 receives the boot failure warning signal from the secure boot control circuit 100, the central processing unit may disable a portion of the functional blocks, modules and / or circuits of the system-on-chip 10 in response to the boot failure warning signal. For another example, when the CPU of the SoC 10 receives the boot failure warning signal from the secure boot control circuit 100 , the CPU may ignore the boot failure warning signal, and the boot process of the SoC 10 may continue to execute.
[0065] In step S360, the secure boot of the system 10 may check the randomness of the output of the entropy source of the secure boot control circuit 100 (e.g., the fingerprint such as the unique pattern 100FP) by calculating a randomness parameter of the output of the entropy source of the secure boot control circuit 100, such as the Hamming weight, to check whether the randomness of the output of the entropy source of the secure boot control circuit 100 (e.g., the randomness parameter such as the Hamming weight) meets a predetermined standard, thereby generating a quality check (QC) result (in Figure 3 (labeled "Fingerprint QC Check OK?" in the figure). If the quality check result indicates "Yes," the process proceeds to step 390; and if the quality check result indicates "No," the process proceeds to step S350. Specifically, if the entropy initialization of the single-chip system 10 is properly performed, after the flag is set, the randomness of the output of the entropy source of the secure boot control circuit 100 (e.g., the fingerprint such as the unique pattern 100FP) can be expected to meet the predetermined standard. If the entropy initialization of a chip is skipped, the randomness of the fingerprint of this chip (e.g., the unique pattern 100FP of the single-chip system 10) will not meet the predetermined standard. Therefore, the quality check result can be used to determine whether the unique pattern 100FP exists (e.g., to determine whether the entropy initialization was properly performed).
[0066] In step S390, the safe boot of the system-on-chip 10 continues (at Figure 3 (The following is marked as "Startup Continue" for simplicity).
[0067] In this embodiment, the operation of checking the randomness of the output of the entropy source of the secure boot control circuit 100 (e.g., the fingerprint such as the unique pattern 100FP) is performed after the flag is set. This ensures that the operation of checking the randomness of the output of the entropy source of the secure boot control circuit 100 (e.g., the fingerprint such as the unique pattern 100FP) is performed only after the existence of the unique pattern 100FP is determined.
[0068] Figure 4 According to an embodiment of the present invention, a method for controlling an electronic device (such as Figure 1 FIG. 4 is a schematic diagram of a safe boot control circuit 40 for a safe boot of a single chip system (SSC) shown in FIG. 4 , wherein the safe boot control circuit 40 is an example of a safe boot control circuit 100. Figure 4As shown, secure boot control circuit 40 includes an anti-tampering circuit 400, a first digital circuit such as a hardened register-transfer level (RTL) circuit 420, and a second digital circuit such as a secure function digital circuit 430. Anti-tampering circuit 400 includes an entropy source 410 (e.g., a physically unclonable function source or a true random number generator). After entropy initialization, entropy source 410 is used to provide a random number sequence (e.g., the fingerprint such as unique pattern 100FP). Hardened RTL circuit 420 is coupled to anti-tampering circuit 400 and is used to control the reading of the random number sequence (e.g., the fingerprint such as unique pattern 100FP). For example, hardened RTL circuit 420 can logically control the output of entropy source 410 to allow the output of entropy source 410 (e.g., the random number sequence) to be read from anti-tampering circuit 400 via a private bus 440. The safety function digital circuit 430 can be coupled to the hardened register transfer stage circuit 420 via the private bus 440 and is used to control the operation of the safe boot of the single chip system 10 (for example, to control the operation of the safe boot of the single chip system 10). Figure 3 The workflow shown). For example, the security function digital circuit 430 can be coupled to the central processing unit of the single-chip system 10 through a standard interface 450, wherein the security function digital circuit 430 receives instructions from the central processing unit of the single-chip system 10, and the security function digital circuit 430 can execute steps corresponding to these instructions and respond to the corresponding data to the central processing unit. Specifically, the security function digital circuit 430 can check the randomness of the output of the entropy source such as the random number sequence (for example, the fingerprint such as the unique pattern 100FP) to generate a check result, and then the security function digital circuit 430 can generate a reference code based on the random number sequence. The security function digital circuit 430 can compare the reference code with an activation code (for example, Figure 1 The activation code 100C shown is compared to generate a comparison result. If the comparison result shows a mismatch, the CPU of the single-chip system 10 receives a startup failure warning and determines the subsequent startup procedure.
[0069] In this embodiment, the entropy source 410 can be implemented based on a hard macro, such as a physically unclonable function-based entropy source utilizing static entropy or a true random number generator-based entropy source utilizing dynamic dithering and post-processing. The output of the physically unclonable function-based entropy source or the true random number generator-based entropy source can have good statistical properties, like a random number, that are difficult or impossible to imitate or crack from outside the secure boot control circuit 40. Furthermore, the output of the physically unclonable function-based entropy source or the true random number generator-based entropy source can be initialized to a fingerprint (such as the unique pattern 100FP) of the system-on-chip 10. For example, after the physically unclonable function-based entropy source or the true random number generator-based entropy source is initialized, the physically unclonable function-based entropy source or the true random number generator-based entropy source can generate a random number sequence (e.g., the fingerprint, such as the unique pattern 100FP) for subsequent use. Furthermore, the anti-tamper circuit 400 further includes analog circuits such as a bandgap circuit and a sense amplifier, which can be implemented based on a custom cell library, such as a proprietary library, and thus cannot or is difficult to reverse engineer. Furthermore, the digital control circuit within the hardened register transfer stage circuit 420 can also be implemented based on a custom cell library. Compared to using a standard cell library provided by a foundry, digital control circuits implemented based on the custom cell library (created by an integrated circuit design company) are less susceptible to reverse engineering.
[0070] Figure 5 According to an embodiment of the present invention, a method for controlling an electronic device (eg Figure 1 The workflow of the method for registering the single-chip system 10 (for example, using a signature device for registration), and Figure 6 According to an embodiment of the present invention, Figure 5 The workflow of the safe power-on control scheme of the electronic device after registration is shown. Figure 5 as well as Figure 6 In the embodiment, it is assumed that the entropy initialization of the electronic device has been completed.
[0071] For easier understanding Figure 5 , please refer to Figures 7 to 9 . Figure 7 A signature device according to an embodiment of the present invention, such as a signature tool 700, is used to perform a single-chip system 70 (which may be Figure 1 The system-on-a-chip 10 or Figure 4 Example of the single chip system 10 shown) Figure 5Schematic diagram of steps S510 to S550. Figure 8 The signature tool 700 according to one embodiment of the present invention is used to execute the single chip system 70 (which may be Figure 1 The system-on-a-chip 10 or Figure 4 Example of the single chip system 10 shown) Figure 5 Schematic diagram of steps S570 to S580. Figure 9 The signature tool 700 according to another embodiment of the present invention is used to execute the single chip system 70 (which may be Figure 1 The system-on-a-chip 10 or Figure 4 Example of the single chip system 10 shown) Figure 5 In some embodiments, the signing tool 700 may be implemented in a Universal Serial Bus (USB) server key / dongle or a computer, but the present invention is not limited thereto. It should be noted that one or more steps may be Figure 5 The steps shown in the following table may be added, modified, or deleted. In addition, these steps do not have to be exactly the same if the same results are achieved. Figure 5 Execute in the order shown.
[0072] In step S510, the signature tool 700 is coupled to the single chip system 70 (for example, coupled to the secure boot control circuit therein such as the secure boot control circuit 100 or 40), the registration process begins, and the signature tool 700 sends a one-time random number (nonce) such as Figure 7 The one-time random number 700N is shown to the single-chip system 70.
[0073] In step S520, the system-on-chip 70 (e.g., a secure boot control circuit within the device) generates a response 70R based on a first shared key of the system-on-chip 70, such as the public key PWD1, and a one-time random number 700N. For example, the system-on-chip 70 may perform a secure hash algorithm (SHA) 71 (labeled "SHA" in the figure for simplicity) on the public key PWD1 of the system-on-chip 70 to generate a result of the secure hash algorithm 71. The system-on-chip 70 may also perform a hash-based message authentication code (HMAC) algorithm 73 (labeled "HMAC" in the figure for simplicity) on the one-time random number 700N and the result of the secure hash algorithm 71 to generate the response 70R and send it to the signing tool 700. In some embodiments, the combination of the secure hash algorithm 71 and the hash-based message authentication code algorithm 73 may be replaced by a cipher-based message authentication code (CMAC) algorithm.
[0074] In step S530, the signature tool 700 generates an encoding result 730C based on a first public key (eg, public key PWD1) of the signature tool 700 and the one-time random number 700N. Figure 7 As shown, the signing tool 700 performs a secure hash algorithm 710 (labeled as "SHA" in the figure for simplicity) on the first public key of the signing tool 700, such as the public key PWD1, to generate a result of the secure hash algorithm 710. The signing tool 700 can also perform a hash-based message authentication code algorithm 730 (labeled as "HMAC" in the figure for simplicity) on the one-time random number 700N and the result of the secure hash algorithm 710 to generate an encoded result 730C. In some embodiments, when the combination of the secure hash algorithm 71 and the hash-based message authentication code algorithm 73 is replaced by the cryptographic-based message authentication code algorithm, the combination of the secure hash algorithm 710 and the hash-based message authentication code algorithm 730 executed by the signing tool 700 can be replaced by the same cryptographic-based message authentication code (CMAC) algorithm as the single-chip system 70.
[0075] In step S550, the signature tool 700 determines whether the response 70R from the single chip system matches the encoded result 730C (in Figure 5(labeled as “70R matches 730C?” for simplicity). For example, the signature tool 700 may utilize the comparator 750 therein to compare the response 70R from the system-on-chip 70 with the encoded result 730C to generate a registration result. If the registration result indicates “yes” (e.g., the response 70R from the system-on-chip 70 matches the encoded result 730C), it indicates that the first public key of the signature tool 700 is consistent with the first public key of the system-on-chip 70 (e.g., the signature tool 700 and the system-on-chip 70 have the same public key, such as PWD1), and the process proceeds to step S570; and if the registration result indicates “no” (e.g., the response 70R from the system-on-chip 70 does not match the encoded result 730C), it indicates that the first public key of the signature tool 700 is inconsistent with the first public key of the system-on-chip 70 (e.g., the system-on-chip 70 may be a counterfeit), and the process proceeds to step S560.
[0076] In step S560, the signature tool 700 issues a signature failure warning. The subsequent operation in response to the signature failure warning can be determined according to the manufacturer's requirements. For example, the signature tool 700 can avoid writing any activation code to the single-chip system 70, and the single-chip system 70 can remain in an inactive state.
[0077] In step S570, the signature tool 700 generates an activation code 74C based on the public key PWD1 and a bit sequence. In one embodiment, the bit sequence may be the public key PWD2 of the signature tool 700, such as Figure 8 In another embodiment, the bit sequence may be a unique identifier (UID) PWD from the single chip system 70. UID (For example, the fingerprint such as Figure 1 The pattern 100FP shown is as follows Figure 9 shown.
[0078] In step S580, the single chip system 70 writes the activation code 74C into the one-time programmable memory 74 (eg, Figure 1 The one-time programmable memory or the one-time programmable memory of the safety power-on control circuit 100 shown in FIG. Figure 4 The one-time programmable memory of the safety power-on control circuit 40 shown in FIG. Figure 5 It is labeled as "Write AC to OTP" for simplicity.
[0079] exist Figure 8In an embodiment of the present invention, the signing tool 700 performs a predetermined algorithm (e.g., a hash-based message authentication code algorithm 730) on the first public key of the signing tool 700 (e.g., public key PWD1) and the second public key of the signing tool 700 (e.g., public key PWD2) to generate an activation code 74C (labeled as "AC" in the figure for simplicity) for writing into the one-time programmable memory 74 (labeled as "OTP" in the figure for simplicity) of the single-chip system 70. For example, the signing tool 700 may perform a secure hash algorithm 710 on the public key PWD1 to generate the result of the secure hash algorithm 710, and further perform a secure hash algorithm 720 (labeled as "SHA" in the figure for simplicity) on the public key PWD2 to generate the result of the secure hash algorithm 720, wherein the signing tool 700 may perform a hash-based message authentication code algorithm 730 on the results of the secure hash algorithm 710 and the secure hash algorithm 720 to generate the activation code 74C. In the present invention, the signing tool 700 performs a predetermined algorithm (e.g., a hash-based message authentication code algorithm 730) on the results of the secure hash algorithm 710 and the secure hash algorithm 720 to generate the activation code 74C. Figure 8 In the illustrated embodiment, the public key PWD2 of the signing tool 700 is pre-stored in the signing tool 700 . For example, the public key PWD2 may be pre-stored in the signing tool 700 before the signing tool 700 performs a registration procedure on the single-chip system 70 .
[0080] exist Figure 9 In the embodiment of the present invention, the fingerprint of the single-chip system 70 is obtained by the entropy source of the single-chip system 70 (e.g. Figure 4 The entropy source 410 shown is provided, and the unique identifier PWD of the single chip system 70 UID The fingerprint may be Figure 1 In order to allow the signature tool 700 to generate the correct activation code (e.g. based on the unique identifier PWD UID Generate activation code 74C), the signature tool 700 can receive the unique identifier PWD from the single chip system 70 after the registration result in step S550 is a match UID For example, the single-chip system 70 may encode a bit sequence such as a unique identifier PWD UID A secure hash algorithm 72 (labeled "SHA" in the figure for simplicity) is performed to generate a result of the secure hash algorithm 72, and the signing tool 700 can receive the result of the secure hash algorithm 72 from the single-chip system 70, wherein the signing tool 700 can perform a hash-based message authentication code algorithm 730 on the secure hash algorithm 710 and the result of the secure hash algorithm 72 to generate an activation code 74C.
[0081] In some embodiments, the signing tool 700 includes a count control 760 that can be used to generate an activation record indicating how many chips have been activated by the signing tool 700. For example, before the signing tool 700 begins the registration process for the system-on-chip 70, the signing tool 700 can check the activation record to determine whether the number of activated chips has reached a predetermined activation threshold. If the activation record indicates that the number of activated chips has not yet reached the predetermined activation threshold, the signing tool 700 can perform the registration process for the system-on-chip 70 and generate the activation code 74C described above. If the activation record indicates that the number of activated chips has reached the predetermined activation threshold, the signing tool 700 will not be able to perform the registration process for the system-on-chip 70 (for example, the registration process will be disabled in response to the activation record indicating that the number of activated chips has reached the predetermined activation threshold), and the system-on-chip 70 will not be activated. Therefore, the number of activated chips can be effectively controlled, thereby preventing the activation of excessively produced chips or overproduction.
[0082] For easier understanding Figure 6 , please refer to Figure 10 as well as Figure 11 . Figure 10 According to an embodiment of the present invention, a control scheme for performing authentication / identification of an activation code on a single chip system 70 is provided. Figure 11 This is a control scheme for authenticating an activation code for a single chip system 70 according to another embodiment of the present invention. It should be noted that one or more steps may be Figure 6 The steps shown in the following table may be added, modified, or deleted. In addition, these steps do not have to be exactly the same if the same results are achieved. Figure 6 Execute in the order shown.
[0083] The operations of steps S610 to S660 are similar to Figure 3 Steps S310 to S360 described in the embodiment are the same and are not repeated here for the sake of brevity. When the quality inspection result of step S660 is displayed as "yes", the process enters step S691.
[0084] In step S691, the system-on-chip 70 generates a public key based on the first public key (eg, public key PWD1) of the system-on-chip 70 and a bit sequence PWD BS Generate reference code 73C (which can be Figure 4 In one embodiment, Figure 8 The public key PWD2 of the single-chip system 70 shown may be a bit sequence PWD BS In another embodiment, Figure 9 The unique identifier PWD of the system-on-chip 70 is shown UIDCan be bit sequence PWD BS example.
[0085] As described in the previous embodiment, the entropy source (eg Figure 4 The flag of the entropy source 410 of the secure boot control circuit 40 may be set in response to the counting result indicating that the period has reached the predetermined time threshold. BS (e.g. unique identifier PWD UID ) can be obtained through Figure 9 The entropy source of the system-on-chip 70 in the embodiment of Figure 4 Therefore, the operation of generating the reference code 73C is performed after the flag is set, which ensures that the operation of generating the reference code 73C is performed at the entropy source of the single-chip system (e.g. Figure 4 The entropy source 410 and its readout circuit are ready to output the bit sequence PWD properly. BS Such as unique identifier PWD UID (For example, the unique pattern 100FP is ready to be output) and then proceed.
[0086] like Figure 10 As shown, the single-chip system 70 can perform a secure hash algorithm 71 on the public key PWD1 to generate a result of the secure hash algorithm 71, and also perform a secure hash algorithm on the bit sequence PWD BS The secure hash algorithm 72 is performed to generate a result of the secure hash algorithm 72, wherein the single-chip system 70 performs a hash-based message authentication code algorithm 73 on the results of the secure hash algorithm 71 and the secure hash algorithm 72 to generate a reference code 73C, and the single-chip system 70 uses a comparator 75 therein to compare the activation code 74C stored in the one-time programmable memory 74 with the reference code 73C to generate a comparison result V CMP In some embodiments, secure hash algorithm 71, secure hash algorithm 72, and hash-based message authentication code algorithm 73 may be replaced by a cryptographic-based message authentication code algorithm 76 (labeled "CMAC" in the figure for simplicity), such as Figure 11 As shown, the reference code 76C generated by the encryption-based message authentication code algorithm 76 can be an example of the reference code 73C, but the present invention is not limited thereto.
[0087] In step S692, the single chip system 70 performs the comparison based on the comparison result V CMP Determine whether the activation code stored in the one-time programmable memory 74 matches the reference code 73C (in Figure 6 is marked as "74C matches 73C?" for simplicity). If the comparison result V CMPDisplaying that the activation code matches the reference code 73C indicates that the correct activation code (eg, activation code 74C) has been stored in the one-time programmable memory 74, and the process proceeds to step S694; and if the comparison result V CMP The display shows that the activation code does not match the reference code 73C, indicating that the single-chip system 70 has not been activated by the signature tool 700, and the process enters step S650.
[0088] In step S694, the authentication of the activation code 74C is completed and successful (in Figure 6 It is marked as "Authentication Successful" for simplicity).
[0089] In summary, the method and secure boot control circuit provided by the embodiments of the present invention can treat the output of the entropy source as a fingerprint of the electronic device containing the secure boot control circuit. In addition, the activation code corresponding to this fingerprint needs to be written into the secure boot control circuit through a signature device. Since the above-mentioned fingerprint cannot or is difficult to be reverse engineered or imitated by analysis tools of related technologies, it is ensured that only the signature tool (which has the same public key as the electronic device) can write the correct activation code into the electronic device. Therefore, the present invention can prevent maliciously imitated chips or over-produced chips from being activated or used.
[0090] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.
Claims
1. A method for controlling a safe startup of an electronic device, characterized in that: The method is applicable to a safe startup control circuit of the electronic device, and the method includes: checking the randomness of an output of an entropy source of the secure boot control circuit to generate a checking result; Providing a random number sequence using the entropy source; generating a reference code according to the random number sequence; comparing the reference code with an activation code stored in the secure boot control circuit to generate a comparison result; as well as Determine whether to enable at least one function of the electronic device according to at least one of the inspection result and the comparison result.
2. The method according to claim 1, wherein The flag of the entropy source is set in response to a period starting from the time when the electronic device is powered on reaching a predetermined threshold, and the operations of checking the randomness of the output of the entropy source and generating the reference code are performed after the flag is set.
3. The method according to claim 1, wherein Determining whether to enable the at least one function of the electronic device according to at least one of the inspection result and the comparison result includes: In response to the checking result indicating that the randomness of the output of the entropy source fails to meet a predetermined standard, a boot failure warning is issued.
4. The method according to claim 1, wherein Determining whether to enable the at least one function of the electronic device according to at least one of the inspection result and the comparison result includes: In response to the comparison result indicating that the activation code cannot match the reference code, a power-on failure warning is issued.
5. The method according to claim 1, wherein Also includes: Performing a registration process on the electronic device using a signature device; and After the registration procedure is completed, the activation code is sent to the electronic device using the signature device, wherein the activation code from the signature device is written into the secure boot control circuit of the electronic device.
6. The method according to claim 5, wherein The registration procedure is used to determine whether a first public key of the signature device is consistent with a first public key of the electronic device.
7. The method according to claim 5, wherein Using the signature device to send the activation code to the electronic device includes: The signature device is used to perform a predetermined algorithm based on a first public key of the signature device and a bit sequence to generate the activation code for being written into the secure boot control circuit of the electronic device.
8. The method according to claim 7, wherein Generating the reference code according to the random number sequence includes: The secure boot control circuit is used to perform the predetermined algorithm based on a first public key of the electronic device and the random number sequence to generate the reference code.
9. The method according to claim 1, wherein The entropy source of the secure boot control circuit is implemented by a static entropy or a dynamic entropy.
10. A method for controlling registration of an electronic device, characterized in that: Include: Using a signature device to send a one-time random number to a secure startup control circuit of the electronic device; generating a response using the secure boot control circuit based on a first public key of the electronic device and the one-time random number; generating a coding result using the signature device based on a first public key of the signature device and the one-time random number; as well as The signature device is used to determine whether to write an activation code into the electronic device, wherein the activation code is generated according to the first public key and a bit sequence.
11. The method according to claim 10, wherein The bit sequence is a second public key of the signature device.
12. The method according to claim 10, wherein The bit sequence is a unique identifier received from the electronic device.
13. A safe startup control circuit for controlling safe startup of an electronic device, characterized in that: The electronic device includes the safe startup control circuit, and the safe startup control circuit includes: an anti-tampering circuit including: an entropy source for providing a random number sequence; a first digital circuit, coupled to the anti-tampering circuit, for controlling the reading of the random number sequence; and a second digital circuit, coupled to the first digital circuit, for controlling a safe startup operation of the electronic device, wherein: The secure boot control circuit checks the randomness of an output of the entropy source of the secure boot control circuit to generate a check result; The secure boot control circuit generates a reference code according to the random number sequence; The second digital circuit compares the reference code with an activation code stored in the secure boot control circuit to generate a comparison result; and The second digital circuit determines whether to enable at least one function of the electronic device according to at least one of the inspection result and the comparison result.
14. The safe startup control circuit according to claim 13, wherein: The flag of the entropy source is set in response to a period starting from the time when the electronic device is powered on reaching a predetermined threshold, and the operations of checking the randomness of the output of the entropy source and generating the reference code are performed after the flag is set.
15. The safe startup control circuit according to claim 13, wherein: When the checking result indicates that the randomness of the output of the entropy source fails to meet a predetermined standard, the secure boot control circuit issues a boot failure warning.
16. The safe startup control circuit according to claim 13, wherein: When the comparison result indicates that the activation code cannot match the reference code, the secure boot control circuit issues a boot failure warning.
17. The safe startup control circuit according to claim 13, wherein: A signature device is coupled to the electronic device to perform a registration procedure on the electronic device, and after the registration procedure is completed, the signature device sends the activation code to the electronic device so that the activation code from the signature device is written into the secure boot control circuit.
18. The safe startup control circuit according to claim 17, wherein: The registration procedure is used to determine whether a first public key of the signature device is consistent with a first public key of the electronic device.
19. The safe startup control circuit according to claim 17, wherein: The signature device performs a predetermined algorithm based on a first public key of the signature device and a bit sequence to generate the activation code for being written into the secure boot control circuit of the electronic device.
20. The safe startup control circuit according to claim 19, wherein: The bit sequence is the random number sequence received from the electronic device after the registration procedure is completed.
21. The safe startup control circuit according to claim 19, wherein: The second digital circuit performs the predetermined algorithm based on a first public key of the electronic device and the random number sequence to generate the reference code.
22. The safe startup control circuit according to claim 13, wherein: The anti-tamper circuit is implemented based on a custom cell library.
Citation Information
Patent Citations
Security system-on-chip
CN108604274A
Cryptographically securing entropy for later use
US20180323967A1